Netdev List
 help / color / mirror / Atom feed
From: Wentao Liang <vulab@iscas.ac.cn>
To: alibuda@linux.alibaba.com
Cc: davem@davemloft.net, dust.li@linux.alibaba.com,
	edumazet@google.com, guwen@linux.alibaba.com, horms@kernel.org,
	kgraul@linux.ibm.com, kuba@kernel.org,
	linux-kernel@vger.kernel.org, linux-rdma@vger.kernel.org,
	linux-s390@vger.kernel.org, mjambigi@linux.ibm.com,
	netdev@vger.kernel.org, pabeni@redhat.com, sidraya@linux.ibm.com,
	tonylu@linux.alibaba.com, wenjia@linux.ibm.com,
	Wentao Liang <vulab@iscas.ac.cn>,
	stable@vger.kernel.org
Subject: [PATCH] net/smc: Fix socket use-after-free in smc_shutdown()
Date: Thu, 17 Sep 2026 16:39:56 +0000	[thread overview]
Message-ID: <20260917163956.2162779-1-vulab@iscas.ac.cn> (raw)

In the fallback path, smc_shutdown() drops the passive closing
reference on the socket with sock_put() and then still uses the socket
by calling release_sock() at the out label. If that reference is the
last one, for example because the passive closing reference was
already consumed by an abort of the active link group, the socket is
freed while it is still in use.

Move the sock_put() after release_sock() so the socket is only dropped
once it is no longer used.

Fixes: 1a74e9932374 ("net/smc: Fix sock leak when release after smc_shutdown()")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
 net/smc/af_smc.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/net/smc/af_smc.c b/net/smc/af_smc.c
index dffbd529762d..420701762c8d 100644
--- a/net/smc/af_smc.c
+++ b/net/smc/af_smc.c
@@ -2943,6 +2943,7 @@ int smc_shutdown(struct socket *sock, int how)
 {
 	struct sock *sk = sock->sk;
 	bool do_shutdown = true;
+	bool passive_close = false;
 	struct smc_sock *smc;
 	int rc = -EINVAL;
 	int old_state;
@@ -2980,7 +2981,7 @@ int smc_shutdown(struct socket *sock, int how)
 		if (sk->sk_shutdown == SHUTDOWN_MASK) {
 			sk->sk_state = SMC_CLOSED;
 			sk->sk_socket->state = SS_UNCONNECTED;
-			sock_put(sk);
+			passive_close = true;
 		}
 		goto out;
 	}
@@ -3011,6 +3012,8 @@ int smc_shutdown(struct socket *sock, int how)
 		sock->state = SS_DISCONNECTING;
 out:
 	release_sock(sk);
+	if (passive_close)
+		sock_put(sk); /* passive closing */
 	return rc ? rc : rc1;
 }
 
-- 
2.34.1


             reply	other threads:[~2026-09-17 16:40 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 16:39 Wentao Liang [this message]
2026-09-21  8:18 ` [PATCH] net/smc: Fix socket use-after-free in smc_shutdown() Dust Li
2026-09-21 15:04 ` krzk
2026-09-21 15:08 ` krzk
2026-09-21 15:16 ` krzk
2026-09-21 17:34 ` netdev-bot+sashiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917163956.2162779-1-vulab@iscas.ac.cn \
    --to=vulab@iscas.ac.cn \
    --cc=alibuda@linux.alibaba.com \
    --cc=davem@davemloft.net \
    --cc=dust.li@linux.alibaba.com \
    --cc=edumazet@google.com \
    --cc=guwen@linux.alibaba.com \
    --cc=horms@kernel.org \
    --cc=kgraul@linux.ibm.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=mjambigi@linux.ibm.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=sidraya@linux.ibm.com \
    --cc=stable@vger.kernel.org \
    --cc=tonylu@linux.alibaba.com \
    --cc=wenjia@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox